Job Category: ELK Engineer
Job Type: Full Time
Job Location: Delhi/NCR
Company Name: One of the leading IT comapny
Your consultant for this Job: karishma - Management 2000 CareerZodiac.comInterested IN this Job?
Yes NoL3 ELK Elastic Stack Engineer overview
The L3 Elastic Stack Engineer is responsible for advanced administration, troubleshooting, and optimization of large-scale Elasticsearch, Logstash/Beats, and Kibana environments in production. The role owns complex incidents, performance issues, upgrades, and integrations, and acts as the final technical escalation point for ELK-related problems.
Key responsibilities
- Operate and support production Elastic Stack clusters (capacity planning, scaling, backup/restore, DR, security hardening, TLS, RBAC).
- Own L3 incidents and problem records related to Elasticsearch indexing/search performance, node failures, data loss, ingestion bottlenecks, and Kibana availability.
- Design and maintain Logstash/Beats pipelines, index templates, ILM policies, and data retention strategies for observability and security use cases.
- Perform upgrades, patching, and version migrations with minimal downtime; validate changes via testing and rollback plans.
- Implement monitoring and alerting for cluster health, resource utilization, and ingestion errors using Kibana, Elastic monitoring, and external tools.
- Collaborate with application, DevOps, security, and SOC teams to onboard new log sources, build dashboards, and tune alerts to reduce noise.
- Create and maintain detailed documentation, runbooks, and knowledge base articles; mentor L1/L2 teams and provide technical guidance.
Required skills and experience
- 8–12 years of overall experience, with 3+ years hands‑on in Elasticsearch/ELK in production (cluster administration, performance tuning, troubleshooting).
- Strong knowledge of Elasticsearch architecture (shards/replicas, mappings, queries/aggregations, ILM, snapshot/restore, security features).
- Experience with Logstash and Beats (Filebeat, Metricbeat, Winlogbeat, etc.) and building reliable ingestion pipelines at scale.
- Proficiency in Linux, networking, and scripting (Bash and/or Python); familiarity with automation/config-management tools such as Ansible or Terraform.
- Experience running ELK on virtualized or cloud platforms (VMware/Hyper‑V, AWS, Azure, or Kubernetes) and integrating with CI/CD.
- Good understanding of logging/monitoring, observability, or SIEM/SOC environments and common security/compliance requirements.
Nice-to-have
- Elastic Certified Engineer or similar Elastic certifications.
- Experience with Elastic Security, APM, or OpenTelemetry integrations.
- Exposure to other observability stacks (Prometheus/Grafana, Splunk, Datadog) for heterogeneous environments.
Salary : Upto : 11.5 LPA